Security Bypass in IBM Tivoli Federated Identity Manager
CVE-2011-3138

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
12 August 2011

What is CVE-2011-3138?

The LTPA STS module in IBM Tivoli Federated Identity Manager versions prior to 6.2.0.9 contains a security flaw where reliance on a static Java Development Kit (JDK) class instance can lead to potential bypass of LTPA token signature verification. This vulnerability arises from inadequate thread safety, allowing malicious actors to exploit this weakness and circumvent security measures designed to protect user authentication, thereby compromising system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.